/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to debian/control

  • Committer: Teddy Hogeborn
  • Date: 2019-02-10 08:41:14 UTC
  • Revision ID: teddy@recompile.se-20190210084114-u91mijrxtifvzra5
Bug fix: Only create TLS key with certtool, and read correct key file

* debian/mandos-client.postinst (create_keys): Remove any bad keys
                                               created by 1.8.0-1.
                                               Only create TLS keys if
                                               certtool succeeds.
* debian/mandos.postinst (configure): Remove any bad keys from
                                      clients.conf, and inform the
                                      user if any were found.
* debian/mandos.templates (mandos/removed_bad_key_ids): New message.
* mandos (MandosServer.handle_ipc): Do not trust a key_id with a known
                                    bad key ID.
* mandos-keygen (keygen): Only create TLS keys if certtool succeeds.
  (password): Bug fix: Generate key_id correctly, and only output
              key_id if TLS key exists.

Show diffs side-by-side

added added

removed removed

Lines of Context:
12
12
        xsltproc, pkg-config, libnl-route-3-dev
13
13
Build-Depends-Indep: systemd, python (>= 2.7), python (<< 3),
14
14
        python-dbus, python-gi
15
 
Standards-Version: 4.2.1
 
15
Standards-Version: 4.3.0
16
16
Vcs-Bzr: https://ftp.recompile.se/pub/mandos/trunk
17
17
Vcs-Browser: https://bzr.recompile.se/loggerhead/mandos/trunk/files
18
18
Homepage: https://www.recompile.se/mandos
25
25
        libgnutls28-dev (<< 3.6.0) | libgnutls30 (<< 3.6.0)
26
26
        | libgnutls30 (>= 3.6.6),
27
27
        python-dbus, python-gi, avahi-daemon, adduser, python-urwid,
28
 
        gnupg2 | gnupg, systemd-sysv | lsb-base (>= 3.0-6)
 
28
        gnupg2 | gnupg, systemd-sysv | lsb-base (>= 3.0-6),
 
29
        debconf (>= 1.5.5) | debconf-2.0
29
30
Recommends: ssh-client | fping
30
31
Description: server giving encrypted passwords to Mandos clients
31
32
 This is the server part of the Mandos system, which allows
47
48
Depends: ${shlibs:Depends}, ${misc:Depends}, adduser,
48
49
        cryptsetup (<< 2:2.0.3-1) | cryptsetup-initramfs,
49
50
        initramfs-tools (>= 0.99), dpkg-dev (>=1.16.0),
50
 
        gnutls-bin (>= 3.6.6) | openssl (>= 1.1.0)
 
51
        gnutls-bin (>= 3.6.6) | openssl (>= 1.1.0),
 
52
        debconf (>= 1.5.5) | debconf-2.0
51
53
Recommends: ssh
52
54
Breaks: dropbear (<= 0.53.1-1)
53
55
Enhances: cryptsetup